๐ฉ๐ช
EGP Abuse Dept
2026-06-15 02:23:21
(5 days ago)
Scanning for port/service exploits on tpc-036.mach3builders.nl
Port Scan
Hacking
๐ธ๐ช
vaia.cloud
2026-06-14 15:09:06
(5 days ago)
trying wp-login.php/xmlrpc.php 34 times in 1 minutes
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 14:16:48
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro. ...
show more
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 10:16:43.567771 2026] [security2:error] [pid 31816:tid 31897] [client 192.145.212.230:43622] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.145.212.230 (+1 hits since last alert)|maryschalkdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "maryschalkdesign.com"] [uri "/xmlrpc.php"] [unique_id "ai63y_HWhTBY9Ss6Bwx04AAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-14 12:01:17
(6 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
dynamix
2026-06-13 16:03:18
(6 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 13:09:31
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro. ...
show more
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 09:09:25.830181 2026] [security2:error] [pid 29927:tid 29927] [client 192.145.212.230:43843] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.145.212.230 (+1 hits since last alert)|eileensharaga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eileensharaga.com"] [uri "/xmlrpc.php"] [unique_id "ai1WhTgBvpZ2Js6w1HkDGAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2026-06-11 19:37:32
(1 week ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
Anonymous
2026-06-11 15:48:10
(1 week ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-11 10:28:37
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro. ...
show more
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 06:28:29.525068 2026] [security2:error] [pid 4791:tid 4791] [client 192.145.212.230:43863] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.145.212.230 (+1 hits since last alert)|casaluzislamujeres.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "casaluzislamujeres.com"] [uri "/xmlrpc.php"] [unique_id "aiqNzcyZuigBMOX_AXItywAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-06-10 20:11:09
(1 week ago)
192.145.212.230 - - [10/Jun/2026:22:10:43 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3719 "-" "Jetpack b ...
show more
192.145.212.230 - - [10/Jun/2026:22:10:43 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3719 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)" 192.145.212.230 - - [10/Jun/2026:22:10:55 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3718 "-" "Jetpack by WordPress.com" 192.145.212.230 - - [10/Jun/2026:22:11:07 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3719 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 19:19:38
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro. ...
show more
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 15:19:33.666654 2026] [security2:error] [pid 28861:tid 28861] [client 192.145.212.230:43759] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.145.212.230 (+1 hits since last alert)|difusionens.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "difusionens.org"] [uri "/xmlrpc.php"] [unique_id "aihnRbgK-8zYhze35u94TQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-09 17:17:39
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
Marc
2026-06-09 17:15:48
(1 week ago)
192.145.212.230 - - [09/Jun/2026:19:15:24 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3718 "-" "WordPress ...
show more
192.145.212.230 - - [09/Jun/2026:19:15:24 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3718 "-" "WordPress.com; https://wordpress.com" 192.145.212.230 - - [09/Jun/2026:19:15:36 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3719 "-" "Jetpack/12.1; WordPress/6.2; http://site14743453.com" 192.145.212.230 - - [09/Jun/2026:19:15:47 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3720 "-" "WordPress.com; https://wordpress.com"
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-07 16:15:51
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 15:47:49
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro. ...
show more
(mod_security) mod_security (id:240335) triggered by 192.145.212.230 (static-212-145-192-230.velpro.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 11:47:42.621455 2026] [security2:error] [pid 22388:tid 22388] [client 192.145.212.230:43990] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.145.212.230 (+1 hits since last alert)|abeltours.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abeltours.com"] [uri "/xmlrpc.php"] [unique_id "aiWSnlRBwtBjd1rNfCqhqQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack